Upgrade to Pro — share decks privately, control downloads, hide ads and more …

Public Cloud London Meetup - Kubernetes at Christmas - 8th December 2022

Public Cloud London Meetup - Kubernetes at Christmas - 8th December 2022

Alessandro Vozza

December 08, 2022
Tweet

More Decks by Alessandro Vozza

Other Decks in Technology

Transcript

  1. 3 | Copyright © 2022 Istio - The Industry’s Leading

    Service Mesh 2017 Istio Launched 2022 Ambient Mesh Launched Data Plane Enhancements 2019-20 7 New Community Releases 1000s Production Customers ~ 1000 Community Contributors 2022 CNCF 2019-2022
  2. 6 | Copyright © 2022 “The best way to predict

    the future is to invent it.” — Alan Kay
  3. 7 | Copyright © 2022 Introducing Istio Ambient Mesh 7

    | Copyright © 2022 A new, open source contribution to the Istio project, that defines a new sidecar-less data plane. Solo.io and Google are the lead contributors to Istio Ambient Mesh. Cost Reduction Simplify Operations Improve Performance
  4. 8 | Copyright © 2022 What is Istio Ambient Mesh?

    P P P P P P P P P P P P P P P P P P Proxy Istio Sidecar Data Plane 1 Pod/Container = 1 Proxy Ambient Mesh Data Plane 1 Node = 1 Proxy Move from Sidecar Proxy per-pod architecture to a Proxy per-node architecture. “Making the Mesh Transparent to Applications” • Reduced Compute Cost • Improve Business Continuity • Increase Business Flexibility • Simplified Operations • Reduced Maintenance • Simplified Upgrades • Easier to Add Applications • Less Day-2-Day Complexity • Adapt to Application Needs • Offer SLAs for Applications • Many Apps = 1 Platform Application Team • Mesh is transparent to Apps • Applications won’t break • Flexible Performance Available • Manage Security vs Performance Business Owner Platform Team
  5. 9 | Copyright © 2022 Istio enables Zero-Trust Security P

    P P P P P P P P P P P P P P P P P L4 Proxy P P P P P P P P P P P P P P P P P P Istio Security with Sidecar Proxy Istio Security with Ambient Mesh L4 Proxy L7 Proxy • All traffic goes through Proxy • Proxy manages mTLS, Identity • Proxy manages L7 Application Filters | Policies • All traffic goes through Proxy • L4 Proxy manages mTLS, Identity • L7 Proxy manages L7 Application Filters | Policies
  6. 10 | Copyright © 2022 Gloo Mesh - The Future

    of Service Mesh Built on Istio P P P P P P P P P P P P Proxy Istio Control Plane Istio Control Plane Multi-Cluster Control Plane Istio Sidecar Data Plane Ambient Mesh Data Plane API Gateway Kubernetes Ingress Microservices Security, Observability Kubernetes CNI Network Policy
  7. 11 | Copyright © 2022 What is Istio Ambient Mesh?

    Reduce Costs Blog: https://www.solo.io/blog/what-istio-ambient-mesh-means-for-your-wallet/
  8. 17 | Copyright © 2022 HBONE - The protocol used

    to connect nodes HTTP Based Overlay Network Encapsulation protocol source: https://www.solo.io/blog/understanding-istio-ambient-ztunnel-and-secure-overlay/
  9. 19 | Copyright © 2022 Demo time The are no

    demo gods | https://github.com/coding-kitties/kubernetes-ambient-service-mesh
  10. 20 | Copyright © 2022 Solo Academy - Our Community

    Expertise is Growing 10,000+ students have attended hands-on workshops 1,800+ engineers have achieved certifications NPS Score 75
  11. 22 | Copyright © 2022 Amsterdam - 23rd& 24th February

    2023 https://cloudnative.amsterdam [email protected] 450+ attendees + talks+workshops+communities = awesome